Microsoft Purview | Insider Risk Management – Personal email triggers
Microsoft Purview Insider Risk Management will add two new email triggers in September 2025 to detect data exfiltration via attachments sent to personal or public email domains. These triggers can be enabled in IRM settings and will update quick policy templates without affecting existing policies. No action required. Introduction To enhance detection capabilities in Insider Risk Management (IRM), we’re adding two new email indicators as triggers for data exfiltration activities. These indicators help identify potential data leaks when users send business-sensitive attachments to personal or public email domains. This update supports stronger data protection and aligns with customer feedback requesting broader coverage of email-based risks. This message is associated with Microsoft 365 Roadmap ID 496149. When this will happen: General Availability (Worldwide, GCC, GCC High, GCC DoD): Rollout will begin in early September 2025 and is expected to complete by late September 2025. How this affects your organization:What you can do to prepare: No action is required. The new triggers will automatically become available for configuration in the IRM policy wizard. Compliance considerations: No compliance considerations identified, review as appropriate for your organization. Who is affected: Admins managing Insider Risk Management policies. What will happen: Two new email triggers will be available: Sending email with attachments to free public domains. Sending email with attachments to self (personal email). These indicators can be enabled from the IRM settings page. Sequence detections will now include these indicators as exfiltration activities. IRM quick policy templates will be updated: Email exfiltration: These two indicators will be set as default triggers and indicators. Sending email with attachments to external recipients will not be enabled by default. Data leaks: Both indicators will be added to triggers and indicators, with no changes to existing ones. Data theft by users leaving your org: Indicators will be added; existing triggers and indicators remain unchanged. Critical asset protection: Both indicators will be added to triggers and indicators, with no changes to existing ones. Existing policies created from quick templates will not be affected. Message ID: MC1147381
The post Microsoft Purview | Insider Risk Management – Personal email triggers appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Purview | Insider Risk Management – Personal email triggers
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Preparing the Windows ecosystem for next-generation code signing
Rollout schedule: Microsoft guidance is already available. October 19, 2026: Microsoft Windows Production PCA 2011 expires. End of 2026: Windo...
Microsoft Viva: Viva Learning retirement of Microsoft 365 training content
Microsoft is retiring 161 Microsoft 365 training modules and selected articles from Viva Learning on September 21, 2026, removing outdated con...
Improved capabilities for files with Copilot in OneDrive Web
Copilot in OneDrive Web enables users with a Microsoft 365 Copilot license to find, understand, analyze, create, and act on files using natura...
Microsoft Teams: Prepare custom apps for private and shared channel compatibility
Microsoft Teams will roll out a feature by September 2026 to help admins identify custom line-of-business apps needing updates for private and...
Microsoft Entra ID: Passkey support for B2B users
Microsoft Entra ID will support passkey registration and sign-in for B2B users to meet resource tenant MFA requirements, enhancing phishing re...
Microsoft 365 admin center: Usage reports migrating to new domains
Microsoft 365 admin center Usage reports domains will change starting mid-August 2026, with current and new domains active in parallel for at ...
Microsoft Teams: Local Pan-tilt-zoom (PTZ) controls for Microsoft Teams Rooms on Windows
Microsoft Teams Rooms on Windows will add native local Pan-Tilt-Zoom (PTZ) camera controls for compatible mechanical or optical PTZ cameras, a...
New in Microsoft 365 Copilot: Self-serve Copilot Connectors
Microsoft 365 Copilot now offers self-serve connectors, allowing users to securely sync external data like Jira and Confluence with their cred...
Microsoft Teams: Admin policy to automatically block identified external meeting bots from joining meetings
Microsoft Teams will introduce a new admin policy, starting August 2026, allowing automatic blocking of identified external meeting bots from ...
Microsoft 365 Copilot: Personalized Copilot Suggestions Coming to Frontier
Microsoft 365 Copilot will introduce personalized AI suggestions in Copilot Chat for eligible Frontier program users starting early August 202...